lang icon English
Nov. 23, 2024, 11:41 a.m.
2464

North Korea's Sapphire Sleet Group Steals $10M in Cryptocurrency

The North Korea-linked hacker group Sapphire Sleet is believed to have stolen over $10 million in cryptocurrency through social engineering campaigns over six months. According to Microsoft, the group has been using fake LinkedIn profiles, posing as recruiters and job seekers to generate money for the nation under sanctions. Active since at least 2020, Sapphire Sleet is related to hacking groups APT38 and BlueNoroff. In November 2023, Microsoft disclosed that the group had set up infrastructure that imitated skills assessment portals for its campaigns. One primary tactic used by Sapphire Sleet involves pretending to be a venture capitalist interested in a target’s company, initiating an online meeting. When targets attempt to join, they encounter error messages urging them to contact the room administrator or support team. If the victim contacts the threat actor, they receive either an AppleScript (. scpt) or Visual Basic Script (. vbs) file, depending on their operating system, under the guise of resolving the issue.

These scripts download malware, allowing attackers access to credentials and cryptocurrency wallets, leading to theft. Sapphire Sleet also impersonates recruiters from financial firms like Goldman Sachs on LinkedIn, luring targets to complete a skills assessment that delivers malware to their devices. Microsoft has noted that North Korea sends thousands of IT workers abroad, creating a revenue stream from "legitimate" work, intellectual property theft, and data theft-for-ransom. These workers use facilitators to access platforms for remote job applications and create fake profiles on sites like GitHub and LinkedIn. In some cases, they employ AI tools like Faceswap to alter stolen photos and documents or to create professional-looking images for resumes and job applications. They also experiment with other AI technologies such as voice-altering software. North Korean IT workers meticulously track their earnings, collectively generating at least $370, 000 through these activities, as per Microsoft’s findings.



Brief news summary

Microsoft has discovered a North Korean-linked hacking group known as Sapphire Sleet, which has stolen over $10 million in cryptocurrency since 2020. Related to groups APT38 and BlueNoroff, Sapphire Sleet employs social engineering by creating fake LinkedIn profiles, masquerading as recruiters or venture capitalists, to target finance professionals. They lure victims into online meetings where they deploy malicious scripts to gain access to credentials and cryptocurrency wallets. Frequently, they impersonate recruiters from prestigious firms like Goldman Sachs, tricking victims into visiting fake skills assessment sites that install malware. Microsoft highlights North Korea's dual approach: using IT workers overseas to earn legitimate income and conduct data theft. These operatives leverage platforms like GitHub and LinkedIn, utilizing AI tools such as Faceswap and voice changers to secure remote jobs and establish credibility. Microsoft's findings reveal that these techniques have generated around $370,000 for the hackers, showcasing their effective exploitation of digital platforms for financial gain.

Watch video about

North Korea's Sapphire Sleet Group Steals $10M in Cryptocurrency

Try our premium solution and start getting clients — at no cost to you

I'm your Content Creator.
Let’s make a post or video and publish it on any social media — ready?

Language

Hot news

Oct. 31, 2025, 6:37 a.m.

Top 12 SEO Trends & Strategies That Deliver Resul…

Search engines continuously update their ranking methods, causing SEO strategies to evolve constantly.

Oct. 31, 2025, 6:25 a.m.

Is Your Sales Team Guilty of AI-Washing? A CRO’s …

Around 2019, before AI became widespread, C-suite leaders’ main concern was getting sales executives to update CRM systems accurately.

Oct. 31, 2025, 6:20 a.m.

AI Video Compression Techniques Improve Streaming…

The rapid evolution of streaming platforms has been greatly driven by advancements in artificial intelligence, especially in video compression.

Oct. 31, 2025, 6:20 a.m.

Dappier Partners with LiveRamp to Enhance AI Adve…

On October 9, 2025, Dappier, a leading AI software company specializing in advanced artificial intelligence, announced a strategic partnership with LiveRamp to enhance ad personalization within publishers’ native AI chat and search products.

Oct. 31, 2025, 6:14 a.m.

Reddit's AI-Powered Advertising Strategy Boosts Q…

Reddit (RDDT.N) announced on Thursday that its fourth-quarter revenue forecast exceeds Wall Street expectations, propelled mainly by increased adoption of its AI-powered advertising tools.

Oct. 31, 2025, 6:13 a.m.

Nicepanel Unveils New AI-Powered Platform for Soc…

Nicepanel, a prominent company in marketing technology solutions, has recently introduced its newest innovation, 'Odyssey AI,' an advanced artificial intelligence-powered platform designed to revolutionize social media marketing strategies.

Oct. 30, 2025, 2:32 p.m.

Bots, Bread and the Battle for the Web

When Honest Businesses Meet the Dark Side of Search Sarah, an artisanal baker, launches Sarah’s Sourdough and improves her SEO by creating a quality website, sharing genuine baking content, writing blog posts, earning local backlinks, and telling her story ethically

All news

AI Company

Launch your AI-powered team to automate Marketing, Sales & Growth

and get clients on autopilot — from social media and search engines. No ads needed

Begin getting your first leads today